PT-2020-4595 · Marketo · Marketo Sales Insight Plugin
Published
2020-10-20
·
Updated
2020-10-22
·
CVE-2020-24416
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Marketo Sales Insight plugin version 1.4355 and earlier
Description
The issue is related to a blind stored Cross-Site Scripting (XSS) vulnerability. This could allow an attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the vulnerable field, malicious JavaScript may be executed in their browser. The vulnerability is also associated with a lack of input data sanitization, which could enable a remote attacker to execute arbitrary JavaScript code.
Recommendations
For Marketo Sales Insight plugin version 1.4355 and earlier, update to a version that addresses the input data sanitization issue and fixes the blind stored Cross-Site Scripting (XSS) vulnerability. As a temporary workaround, consider restricting access to vulnerable form fields to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marketo Sales Insight Plugin